Description
WordPress Plugin WordPress Poll is prone to multiple SQL injection and security bypass vulnerabilities. Exploiting these issues could allow an attacker to bypass certain security restrictions and perform unauthorized actions, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin WordPress Poll version 34.04 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 35.0 or latest
References
http://www.girlinthemiddle.net/2013/01/multiple-sql-injection-vulnerabilities.html
http://packetstormsecurity.com/files/119736/Cardoza-WordPress-Poll-34.05-SQL-Injection.html
http://seclists.org/bugtraq/2013/Jan/86
Related Vulnerabilities
MySQL CVE-2020-14591 Vulnerability (CVE-2020-14591)
SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-1102)
MySQL CVE-2021-35630 Vulnerability (CVE-2021-35630)
WordPress Plugin Chat Room Directory Traversal (0.1.2)
WordPress Plugin Ivory Search-WordPress Search Cross-Site Scripting (4.6.6)